]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
qemu: migration: Use TLS environment for NBD server if requested
authorPeter Krempa <pkrempa@redhat.com>
Wed, 21 Feb 2018 15:55:15 +0000 (16:55 +0100)
committerPeter Krempa <pkrempa@redhat.com>
Mon, 30 Apr 2018 12:58:05 +0000 (14:58 +0200)
Use the TLS env for migration when starting the NBD server if TLS is
enabled for migration.

Signed-off-by: Peter Krempa <pkrempa@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
src/qemu/qemu_migration.c

index a54263f39c30fcf4f64c24c5271ffb5804f9c4ce..ec52846130355d563ee53384db02a1088c1b8485 100644 (file)
@@ -369,7 +369,8 @@ qemuMigrationDstStartNBDServer(virQEMUDriverPtr driver,
                                const char *listenAddr,
                                size_t nmigrate_disks,
                                const char **migrate_disks,
-                               int nbdPort)
+                               int nbdPort,
+                               const char *tls_alias)
 {
     int ret = -1;
     qemuDomainObjPrivatePtr priv = vm->privateData;
@@ -411,7 +412,7 @@ qemuMigrationDstStartNBDServer(virQEMUDriverPtr driver,
             else if (virPortAllocatorAcquire(driver->migrationPorts, &port) < 0)
                 goto exit_monitor;
 
-            if (qemuMonitorNBDServerStart(priv->mon, listenAddr, port, NULL) < 0)
+            if (qemuMonitorNBDServerStart(priv->mon, listenAddr, port, tls_alias) < 0)
                 goto exit_monitor;
         }
 
@@ -2401,9 +2402,21 @@ qemuMigrationDstPrepareAny(virQEMUDriverPtr driver,
     if (mig->nbd &&
         flags & (VIR_MIGRATE_NON_SHARED_DISK | VIR_MIGRATE_NON_SHARED_INC) &&
         virQEMUCapsGet(priv->qemuCaps, QEMU_CAPS_NBD_SERVER)) {
+        const char *nbdTLSAlias = NULL;
+
+        if (flags & VIR_MIGRATE_TLS) {
+            if (!virQEMUCapsGet(priv->qemuCaps, QEMU_CAPS_NBD_TLS)) {
+                virReportError(VIR_ERR_OPERATION_UNSUPPORTED, "%s",
+                               _("QEMU NBD server does not support TLS transport"));
+                goto stopjob;
+            }
+
+            nbdTLSAlias = tlsAlias;
+        }
+
         if (qemuMigrationDstStartNBDServer(driver, vm, incoming->address,
                                            nmigrate_disks, migrate_disks,
-                                           nbdPort) < 0) {
+                                           nbdPort, nbdTLSAlias) < 0) {
             goto stopjob;
         }
         cookieFlags |= QEMU_MIGRATION_COOKIE_NBD;